Recent Advisories

Severity ID Title Vendor Product Date Type
NONE MSF:PAYLOAD-CMD-

HTTPS Fetch, Linux Execute Command_MSF:PAYLOAD-CMD-LINUX-HTTPS-AARCH64-EXEC-

Fetch and execute an AARCH64 payload from an HTTPS server. Execute an arbitrary command or just a /bin/sh shell Module Options msf use payload/cmd/...

N/A N/A METASPLOIT
NONE MSF:PAYLOAD-CMD-

TFTP Fetch, Linux Execute Command_MSF:PAYLOAD-CMD-LINUX-TFTP-AARCH64-EXEC-

Fetch and execute an AARCH64 payload from a TFTP server. Execute an arbitrary command or just a /bin/sh shell Module Options msf use payload/cmd/li...

N/A N/A METASPLOIT
NONE MSF:PAYLOAD-LINUX-

Linux Execute Command_MSF:PAYLOAD-LINUX-AARCH64-EXEC-

Execute an arbitrary command or just a /bin/sh shell Module Options msf use payload/linux/aarch64/exec msf payloadexec show actions ...actions... m...

N/A N/A METASPLOIT
NONE MSF:AUXILIARY-SERVER-

Microsoft Windows HTTP to LDAP Relay_MSF:AUXILIARY-SERVER-RELAY-HTTP_TO_LDAP-

This module supports running an HTTP server which validates credentials, and then attempts to execute a relay attack against an LDAP server on the ...

N/A N/A METASPLOIT
CRITICAL 9.8 MSF:EXPLOIT-MULTI-

Langflow RCE_MSF:EXPLOIT-MULTI-HTTP-LANGFLOW_RCE_CVE_2026_27966-

The CSV Agent node in Langflow hardcodes allowdangerouscode=True, which automatically exposes LangChain's Python REPL tool pythonreplast. As a resu...

N/A N/A METASPLOIT
HIGH 8.7 MSF:EXPLOIT-MULTI-

WebDAV PHP Upload_MSF:EXPLOIT-MULTI-HTTP-WEBDAV_UPLOAD_PHP-

This module exploits WebDAV which also has PHP enabled, such as found on XAMPP servers. It can use do by using any supplied credentials to upload v...

N/A N/A METASPLOIT
HIGH 7.7 MSF:AUXILIARY-GATHER-

Camaleon CMS Directory Traversal CVE-2024-46987_MSF:AUXILIARY-GATHER-CAMALEON_DOWNLOAD_PRIVATE_FILE-

Exploits CVE-2024-46987, an authenticated directory traversal vulnerability in Camaleon CMS versions use auxiliary/gather/camaleondownloadprivatefi...

N/A N/A METASPLOIT
CRITICAL 9.1 MSF:EXPLOIT-MULTI-

ChurchCRM Database Restore RCE 6.2.0_MSF:EXPLOIT-MULTI-HTTP-CHURCHCRM_DB_RESTORE_RCE-

This module exploits a Remote Code Execution RCE vulnerability in ChurchCRM versions prior to 6.2.0. The vulnerability resides in the Database Rest...

N/A N/A METASPLOIT
NONE MSF:PAYLOAD-LINUX-

Linux Chmod_MSF:PAYLOAD-LINUX-LOONGARCH64-CHMOD-

Runs chmod on the specified file with specified mode. Module Options msf use payload/linux/loongarch64/chmod msf payloadchmod show actions ...actio...

N/A N/A METASPLOIT
NONE MSF:EXPLOIT-WINDOWS-

Windows Persistence Bits Job_MSF:EXPLOIT-WINDOWS-PERSISTENCE-BITS-

This module establishes persistence through a BITS job that downloads and executes a payload. Background Intelligent Transfer Service BITS is a Win...

N/A N/A METASPLOIT